... k and controls * Fosters relationships with IT and business personnel at appropriate levels and serve as a subject matter expert for IT control design, system access, change management, data ...
... k and controls * Fosters relationships with IT and business personnel at appropriate levels and serve as a subject matter expert for IT control design, system access, change management, data ...
Managing reporting and communications for leadership on risk, compliance, and operational ... Work you'll do As an Associate Director, Risk and Compliance on the Independence & Conflicts ...
Managing reporting and communications for leadership on risk, compliance, and operational ... Work you'll do As an Associate Director, Risk and Compliance on the Independence & Conflicts ...
Experience operationalizing AI governance aligned to the National Institute of Standards and Technology AI Risk Management Framework or ISO/IEC 42001. * Experience with generative AI safety and ...
Experience operationalizing AI governance aligned to the National Institute of Standards and Technology AI Risk Management Framework or ISO/IEC 42001. * Experience with generative AI safety and ...
The Safety Director drives alignment between safety and operations through early engagement, planning influence, and the use of direct control to manage risk. Key Responsibilities * Provide ...
The Safety Director drives alignment between safety and operations through early engagement, planning influence, and the use of direct control to manage risk. Key Responsibilities * Provide ...
Compliance/Risk Manager -HEALTH/SAFETY
Elizabethtown, KY · On-site
$55K - $65K/yr
Director of Operations Work Location: CBO, Elizabethtown, Ky. 42701 Status: N Pre-Employment ... Develop and maintain a risk management plan * Develop and maintain a risk/hazard observation ...
Compliance/Risk Manager -HEALTH/SAFETY
Elizabethtown, KY · On-site
$55K - $65K/yr
Director of Operations Work Location: CBO, Elizabethtown, Ky. 42701 Status: N Pre-Employment ... Develop and maintain a risk management plan * Develop and maintain a risk/hazard observation ...
Compliance/Risk Manager -HEALTH/SAFETY
Elizabethtown, KY · On-site
$55K - $65K/yr
Director of Operations Work Location: CBO, Elizabethtown, Ky. 42701 Status: N Pre-Employment ... Develop and maintain a risk management plan * Develop and maintain a risk/hazard observation ...
Compliance/Risk Manager -HEALTH/SAFETY
Elizabethtown, KY · On-site
$55K - $65K/yr
Director of Operations Work Location: CBO, Elizabethtown, Ky. 42701 Status: N Pre-Employment ... Develop and maintain a risk management plan * Develop and maintain a risk/hazard observation ...
We provide cutting-edge technology and a network of owned and operated fulfillment centers that ... Develop and manage the budget for safety, loss prevention, and risk management initiatives ...
We provide cutting-edge technology and a network of owned and operated fulfillment centers that ... Develop and manage the budget for safety, loss prevention, and risk management initiatives ...
Safety Director
Lexington, KY · On-site
The Safety Director drives alignment between safety and operations through early engagement, planning influence, and the use of direct control to manage risk. Key Responsibilities * Provide ...
Safety Director
Lexington, KY · On-site
The Safety Director drives alignment between safety and operations through early engagement, planning influence, and the use of direct control to manage risk. Key Responsibilities * Provide ...
... Enterprise Risk Management Committee, New Activities Risk Committee, Information Technology ... directed Minimum Job Requirements: Education: * Bachelor's degree in Information Security ...
... Enterprise Risk Management Committee, New Activities Risk Committee, Information Technology ... directed Minimum Job Requirements: Education: * Bachelor's degree in Information Security ...
Senior Manager GRC
Louisville, KY · On-site
Ensuring consistent control implementation and enforcement across IT, cloud, and business environments * Leading exception management processes to ensure risk is explicitly understood and accepted at ...
Senior Manager GRC
Louisville, KY · On-site
Ensuring consistent control implementation and enforcement across IT, cloud, and business environments * Leading exception management processes to ensure risk is explicitly understood and accepted at ...
Senior Manager GRC
Louisville, KY · On-site
Ensuring consistent control implementation and enforcement across IT, cloud, and business environments * Leading exception management processes to ensure risk is explicitly understood and accepted at ...
Senior Manager GRC
Louisville, KY · On-site
Ensuring consistent control implementation and enforcement across IT, cloud, and business environments * Leading exception management processes to ensure risk is explicitly understood and accepted at ...
Clinical Risk Nurse Paralegal/UKHC
Lexington, KY · On-site
$71K - $131K/yr
Reporting to the Director of Risk Management and Risk Litigation Counsel, this role supports the investigation, analysis, and management of clinical events and Patient Safety Work Product (PSWP ...
Clinical Risk Nurse Paralegal/UKHC
Lexington, KY · On-site
$71K - $131K/yr
Reporting to the Director of Risk Management and Risk Litigation Counsel, this role supports the investigation, analysis, and management of clinical events and Patient Safety Work Product (PSWP ...
The Execution & Integration Director will provide overarching leadership for the CIWS execution of ... Risk Management: Lead risk identification, mitigation, and escalation processes to ensure program ...
The Execution & Integration Director will provide overarching leadership for the CIWS execution of ... Risk Management: Lead risk identification, mitigation, and escalation processes to ensure program ...
... Risk Management Committee, New Activities Risk Committee, Information Technology Steering Committee, and others as assigned • Serve as the Chair of the Information Security Risk Management ...
... Risk Management Committee, New Activities Risk Committee, Information Technology Steering Committee, and others as assigned • Serve as the Chair of the Information Security Risk Management ...
Director Infrastructure
Walton, KY · On-site
Security & Risk Management * Ensure that IT infrastructure processes are compliant with company ... directed and self-regulated, while being accountable for his/her area of ownership and role • ...
Director Infrastructure
Walton, KY · On-site
Security & Risk Management * Ensure that IT infrastructure processes are compliant with company ... directed and self-regulated, while being accountable for his/her area of ownership and role • ...
Security & Risk Management * Ensure that IT infrastructure processes are compliant with company ... directed and self-regulated, while being accountable for his/her area of ownership and role · ...
Security & Risk Management * Ensure that IT infrastructure processes are compliant with company ... directed and self-regulated, while being accountable for his/her area of ownership and role · ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Senior Property Risk Engineer
Louisville, KY · On-site +1
$126K - $208K/yr
Imagine loving what you do and where you do it. Job Category Risk Control Compensation Overview The ... the Director's absence, meeting attendance.) This position influences but does not manage others.
Senior Property Risk Engineer
Louisville, KY · On-site +1
$126K - $208K/yr
Imagine loving what you do and where you do it. Job Category Risk Control Compensation Overview The ... the Director's absence, meeting attendance.) This position influences but does not manage others.
Senior Property Risk Engineer
Lexington, KY · On-site +1
$126K - $208K/yr
Imagine loving what you do and where you do it. Job Category Risk Control Compensation Overview The ... the Director's absence, meeting attendance.) This position influences but does not manage others.
Senior Property Risk Engineer
Lexington, KY · On-site +1
$126K - $208K/yr
Imagine loving what you do and where you do it. Job Category Risk Control Compensation Overview The ... the Director's absence, meeting attendance.) This position influences but does not manage others.
Monitor SaaS providers compliance using risk-based approaches and performance signals. * Partner cross-functionally (Vendor Management, IT, and Business teams) to ensure alignment on quality ...
Monitor SaaS providers compliance using risk-based approaches and performance signals. * Partner cross-functionally (Vendor Management, IT, and Business teams) to ensure alignment on quality ...
Director Technology Risk Management information
What does a Director of Technology Risk Management do?
How does a Director of Technology Risk Management typically collaborate with other departments to ensure effective risk mitigation?
What are the key skills and qualifications needed to thrive as a Director of Technology Risk Management, and why are they important?
What is the difference between Director Technology Risk Management vs Cybersecurity Manager?
| Aspect | Director Technology Risk Management | Cybersecurity Manager |
|---|---|---|
| Primary Focus | Overseeing technology risk strategies and enterprise risk mitigation | Managing cybersecurity operations and security measures |
| Certifications | CRISC, CISSP, CISM | CISSP, CISA, CEH |
| Work Environment | Strategic, cross-departmental, executive level | Operational, technical teams, security operations centers |
| Industry Usage | Financial, healthcare, large enterprises | IT security firms, corporate IT departments |
The main difference is that the Director Technology Risk Management focuses on broad technology risk strategies across the organization, while the Cybersecurity Manager concentrates on implementing and managing cybersecurity measures. Both roles require similar certifications but differ in scope and strategic versus operational responsibilities.
BrightSpring Health Services rating
4.6
Based on 61 frontline employees who took The Breakroom Quiz
213th of 228 rated social care providers
Job description
BrightSpring Health Services
The IT Internal Audit Lead supports the execution of the SOX 404 program with a focus on IT risks and controls and independently performs riskbased IT and technologyenabled audits. This role partners with IT and business stakeholders, cosourced providers, and other assurance functions to deliver timely, highquality assurance and actionable insights related to systems, applications, and data. As the Internal Audit function continues to mature and expand, this role is expected to grow in breadth and scope, taking on increasing responsibility across IT audit coverage, emerging technology risks, and assurance coordination.
- The IT Internal Audit Lead works with the Vice President of Internal Audit, IT leadership, and business stakeholders to execute the Company’s internal audit plan, with emphasis on IT risk and controls
- Fosters relationships with IT and business personnel at appropriate levels and serve as a subject matter expert for IT control design, system access, change management, data integrity, and documentation standards
- Consistently deliver highquality IT internal audit services in accordance with applicable professional standards (IIA, ISACA)
- Contributes to the annual audit plan and periodic risk updates, partnering with other assurance providers to coordinate activities and enhance overall assurance coverage across IT risks
- Independently plan and execute riskbased IT and technologyenabled audits, including defining objectives and scope, developing test procedures, performing fieldwork, synthesizing findings, assessing impact, and recommending practical, actionable remediation
- Drives highquality work products within expected time frames and budget
- Coordinates multiple concurrent projects and proactively manage stakeholder expectations related to service delivery and timelines
- Stays abreast of current technology, cybersecurity, and industry risk trends
- Performs other duties as assigned
- Supports execution of the SOX 404 program related to IT General Controls (ITGCs), automated application controls, and systemdependent controls, coordinating closely with thirdparty service providers
- Facilitates and lead IT SOX walkthroughs and design effectiveness assessments, including evaluation of:
- logical access controls,
- change management,
- IT operations,
- system interfaces, and
- ITdependent manual controls and IPE completeness and accuracy
- Oversee and review cosourced operating effectiveness testing of IT controls, ensuring testing approaches, evidence, and conclusions meet Internal Audit standards and support external auditor reliance
- Perform operating effectiveness testing as needed, validate systemgenerated evidence, and ensure conclusions are supportable, clearly documented, and auditready
- Provide daytoday oversight and project management of cosourced resources supporting SOX IT and IT audit engagements, including coordinating scope, timelines, deliverables, and reviewing workpapers for quality and consistency
- Serve as one of the primary points of contact for assigned cosource engagements, facilitating communication, resolving issues, and escalating risks or delivery concerns as appropriate
- Independently manage and execute assigned IT audit engagements endtoend, while balancing oversight responsibilities and ensuring alignment with Internal Audit standards and expectations
- Supervisory Responsibility: Yes
- Bachelor’s degree in Information Systems, Computer Science, Accounting, Finance, or a related field.
- 5–7+ years of experience in Internal Audit, IT Audit, or external audit (Big 4 or national firm strongly preferred), with substantial:
- SOX ITGC ownership, and
- hands on IT audit or technology risk assessment experience.
- Experience auditing ERP environments (e.g., SAP, Oracle), key business applications, and supporting infrastructure preferred.
- Industry experience in healthcare, provider services, pharmacy services, or other regulated environments preferred.
- CISA strongly preferred; CIA or CPA a plus
- Strong knowledge of ITGCs, SOX/PCAOB expectations, COSO, COBIT, and IIA/ISACA standards.
- Experience evaluating IT dependent manual controls, automated controls, system interfaces, and reports used as IPE.
- Proficiency with audit management platforms (e.g., Workiva, AuditBoard, TeamMate).
- Strong analytical and data evaluation skills; familiarity with data analytics or continuous auditing concepts is a plus.
- Excellent written and verbal communication skills, with the ability to explain technical concepts to non technical stakeholders.
- Percentage of Travel: 0-25%
**To perform this role will require frequently sitting and typing on a keyboard with fingers, and occasionally standing, walking, and climbing (stairs/ladders). The physical requirements will be the ability to push/pull and lift/carry 1-10 lbs**
BrightSpring Health Services provides complementary home- and community-based health solutions for complex populations in need of specialized and/or chronic care. Through the Companys service lines, including pharmacy, home health care, and rehabilitation, we provide comprehensive and more integrated care and clinical solutions in all 50 states to over 475,000 customers, clients and patients daily. BrightSpring has consistently demonstrated strong and industry-leading quality metrics across its services lines, while improving the health and quality of life for high-need individuals and reducing overall healthcare system costs.For more information, please visit www.brightspringhealth.com. Follow us on Facebook, LinkedIn, and X.
What BrightSpring Health Services employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About BrightSpring Health Services
Sourced by ZipRecruiter
Industry
Health care and social assistance
Company size
10,000+ Employees
Headquarters location
Louisville, KY, US
Year founded
1974